Macao — Cyber Threat Profile

Macao anchors its cyber regime in the Cybersecurity Law (Law No. 13/2019), in force since December 2019, requiring critical infrastructure operators to report incidents to CARIC, the Judiciary Police's 24/7 incident alert and response centre; MOCERT, the territory's FIRST-member CERT, covers community incident response. Exposure centres on the casino economy — gaming taxes supplied about 81% of government revenue in 2024 — which draws espionage interest: the DarkHotel APT spear-phished 17 Macao luxury hotels in late 2021-early 2022. In July 2024 a suspected foreign DDoS took five government security websites offline, and officials report attacks on critical infrastructure more than tripled since 2020. IntelFusions has logged three ransomware leak-site claims against Macao organizations since 2024, two in hospitality and gaming.

Threat actors targeting Macao

Most targeted sectors

Recent claimed incidents

Read the full analysis on IntelFusions